CTIPilot

BlueKeep, Windows RDP pre-auth RCE (2019), exploited by NightEagle/APT-Q-95 for local-account creation and by BlueMoon-adjacent chains historically

cve · CVE-2019-0708 single-source

Coverage timeline
1
first 2026-09-21 → last 2026-09-21
Peak priority
high
1 high
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
5
see Co-occurring entities below
ATT&CK techniques
12
pinned v19.2 · see below

ATT&CK techniques

12 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Execution TA0002

T1053.002Scheduled Task/Job: At×1

Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. In addition to explicitly running the `at` command, adversaries may also schedule a task with at by directly leveraging the Windows Management Instrumentation `Win32_ScheduledJob` WMI class.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Persistence TA0003

T1053.002Scheduled Task/Job: At×1

Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. In addition to explicitly running the `at` command, adversaries may also schedule a task with at by directly leveraging the Windows Management Instrumentation `Win32_ScheduledJob` WMI class.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Privilege Escalation TA0004

T1053.002Scheduled Task/Job: At×1

Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at utility exists as an executable within Windows, Linux, and macOS for scheduling tasks at a specified time and date. Although deprecated in favor of Scheduled Task's schtasks in Windows environments, using at requires that the Task Scheduler service be running, and the user to be logged on as a member of the local Administrators group. In addition to explicitly running the `at` command, adversaries may also schedule a task with at by directly leveraging the Windows Management Instrumentation `Win32_ScheduledJob` WMI class.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Credential Access TA0006

T1003.006OS Credential Dumping: DCSync×1

Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1558Steal or Forge Kerberos Tickets×1

Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Lateral Movement TA0008

T1210Exploitation of Remote Services×1

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Command and Control TA0011

T1090.001Proxy: Internal Proxy×1

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-21/nighteagle-apt-q-95-ghostcontainer-devtunnels-rdp2tcp-dcsync · ATT&CK page ↗

Story timeline

  1. 2026-09-21NightEagle (APT-Q-95) pivots to Russian targets, tunnels RDP through Microsoft's own legitimate dev-tunnels service, and DCSyncs domain credentials after exploiting BlueKeep
    active-threatsKaspersky: an APT group that abused Microsoft's own developer-tunnel feature to expose RDP outward, then chained BlueKeep into a full DCSync credential dump

Where this entity is cited

  • active-threats1

Source distribution

  • securelist.com1 (100%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about BlueKeep, Windows RDP pre-auth RCE (2019), exploited by NightEagle/APT-Q-95 for local-account creation and by BlueMoon-adjacent chains historically (1)

2026-09-21 · view entry permalink →

HIGHCVE-2020-0688 +1exploitedNATOB2

NightEagle (APT-Q-95) pivots to Russian targets, tunnels RDP through Microsoft's own legitimate dev-tunnels service, and DCSyncs domain credentials after exploiting BlueKeep

Kaspersky's Global Emergency Response Team documents a NightEagle (also tracked as APT-Q-95) campaign, active since at least 2023 and previously focused on Asian targets, now confirmed against organizations in Russia (Kaspersky Securelist, 2026-09-16). Initial access used compromised VPN credentials, with connections originating from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from European VPS ranges. On Microsoft Exchange servers the group deploys the GhostContainer backdoor, a .NET assembly that incorporates the Neo-reGeorg tunnel, an exploit component for CVE-2020-0688, and the GhostWebShell class from the ysoserial utility; Kaspersky assesses with high confidence that delivery reused a technique it had already documented, extracting Exchange's own ASP.NET machine keys, then overwriting the VIEWSTATE framework parameter and injecting a payload into it to launch the backdoor in memory. Once running, the backdoor evades detection by patching addresses in amsi.dll and ntdll.dll, blinding both the Antimalware Scan Interface and Windows Event Logging.

For network access, NightEagle abuses Microsoft's own legitimate dev-tunnels feature (*.devtunnels.ms), a service meant to publish local developer web services to the internet, to expose port 3389 (RDP) outward on the compromised host, then layers rdp2tcp, a public RDP-virtual-channel TCP tunneling tool, inside that RDP session; a combination Kaspersky states lets the group maintain network access using legitimate services, without opening any additional suspicious port. Staged payloads on GitHub carry mismatched legitimate-sounding filenames (adobe_32.exe, 1c-office-plugin.exe, trueconf-broker.exe) to blend in with normal software update or business-communication traffic. For lateral movement and privilege escalation, NightEagle exploited CVE-2019-0708 (BlueKeep) in one incident to create and elevate a local account into the Administrators and Remote Desktop Users groups, used Impacket's atexec to set scheduled netsh portproxy rules for internal port forwarding, and requested Kerberos tickets carrying a non-standard Forwardable/Proxiable/Renewable flag combination before executing DCSync against the Domain-Password object to dump domain credentials by impersonating the domain controller.

Triage: Microsoft dev-tunnels traffic to *.devtunnels.ms is legitimate on developer workstations running Visual Studio or the Dev Tunnels CLI; the discriminator is the host class: a production server, domain controller, or non-developer endpoint establishing an outbound dev-tunnels connection has no legitimate reason to do so.

We have now identified attacks by the group targeting businesses in Russia.

This is a legitimate Microsoft mechanism that allows local web services to be published for internet access on ..devtunnels.ms domains. The attackers used this tunneling capability to expose port 3389 (RDP) on the compromised system.

In one incident, they exploited a well-known RDP implementation vulnerability, CVE-2019-0708 (BlueKeep). They used the vulnerable mechanism to create a local account on the system and add it to the Administrators and Remote Desktop Users groups.

The attackers also requested Kerberos tickets with a non-standard combination of flags (Forwardable, Proxiable, Renewable) and attempted to replicate the Domain-Password object from the Active Directory database to impersonate the domain controller (a technique known as DCSync) after obtaining an account with sufficient privileges.

Kaspersky Securelist (GERT) 2026-09-16
threat21 Sep 04:42Zsingle-sourceOpen finding ↗